Exam Details

  • Exam Code
    :300-715
  • Exam Name
    :Implementing and Configuring Cisco Identity Services Engine (SISE)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :404 Q&As
  • Last Updated
    :Mar 28, 2025

Cisco CCNP Security 300-715 Questions & Answers

  • Question 31:

    An engineer is working on a switch and must tag packets with SGT values such that it learns via SXP. Which command must be entered to meet this requirement?

    A. ip source guard

    B. ip dhcp snooping

    C. ip device tracking maximum

    D. ip arp inspection

  • Question 32:

    A network security administrator needs a web authentication configuration when a guest user connects to the network with a wireless connection using these steps:

    An initial MAB request is sent to the Cisco ISE node.

    Cisco ISE responds with a URL redirection authorization profile if the user's MAC address is unknown in the endpoint identity store.

    The URL redirection presents the user with an AUP acceptance page when the user attempts to go to any URL.

    Which authentication must the administrator configure on Cisco ISE?

    A. device registration WebAuth

    B. WLC with local WebAuth

    C. wired NAD with local WebAuth

    D. NAD with central WebAuth

  • Question 33:

    An engineer is adding a new network device to be used with 802.1X authentication. After configuring the device, the engineer notices that no endpoints that connect to the switch are able to authenticate. What is the problem?

    A. The command dot1x system-auth-control is not configured on the switch.

    B. The switch's supplicant is unable to establish a connection to Cisco ISE.

    C. The command dot1x critical vlan 40 is not configured on the switch ports.

    D. The endpoint firewalls are blocking the EAPoL traffic.

  • Question 34:

    An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which configuration must be applied on Cisco ISE?

    A. Use a third-party certificate on the network device.

    B. Add the device to all PSN nodes in the deployment.

    C. Renew the expired certificate on one of the PSN.

    D. Configure an authorization profile for the end users.

  • Question 35:

    An engineer is starting to implement a wired 802.1X project throughout the campus. The task is for failed authentication to be logged to Cisco ISE and also have a minimal impact on the users. Which command must the engineer configure?

    A. authentication open

    B. pae dot1x enabled

    C. authentication host-mode multi-auth

    D. monitor-mode enabled

  • Question 36:

    A network engineer is in the predeployment discovery phase of a Cisco ISE deployment and must discover the network. There is an existing NMS in the network. Which type of probe must be configured to gather the information?

    A. SNMP

    B. NMAP

    C. NetFlow

    D. RADIUS

  • Question 37:

    An engineer must organize endpoints in a Cisco ISE identity management store to improve the operational management of IP phone endpoints. The endpoints must meet these requirements:

    1.

    classify endpoints for finance, sales, and marketing departments

    2.

    tag each endpoint as profiled

    Which action organizes the endpoints?

    A. Add a tag for the endpoints of each department and use the identity group filter.

    B. Create an endpoint identity group for each department with the profiled parent group.

    C. Add a tag for the endpoints of each department and add an endpoint to profiled group.

    D. Create an endpoint identity group for each department with the IP phone parent group.

  • Question 38:

    A network engineer must remove a device that has been allowlisted. How should the engineer remove it manually on Cisco ISE?

    A. Administration > Identity Management > Endpoint Identity Groups > Profiled

    B. Administration > Identity Management > Groups > Endpoint Identity Groups

    C. Administration > Identity Management > Groups > Endpoint Identity Groups > Profiled

    D. Administration > Identity Management > Endpoint Identity Groups

  • Question 39:

    Which file setup method is supported by ZTP on physical appliances?

    A. cfg

    B. iso

    C. img

    D. ova

  • Question 40:

    What is configured to enforce the blocklist permissions and deny access to clients in the blocklist to protect against a lost or stolen device obtaining access to the network?

    A. My Devices portal

    B. blocklist portal

    C. Authentication rule

    D. Authorization rule

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-715 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.